AI Chat Paper
Note: Please note that the following content is generated by AMiner AI. SciOpen does not take any responsibility related to this content.
{{lang === 'zh_CN' ? '文章概述' : 'Summary'}}
{{lang === 'en_US' ? '中' : 'Eng'}}
Chat more with AI
PDF (7.1 MB)
Collect
Submit Manuscript AI Chat Paper
Show Outline
Outline
Show full outline
Hide outline
Outline
Show full outline
Hide outline
Open Access

A Novel Hybrid Method to Analyze Security Vulnerabilities in Android Applications

Junwei TangRuixuan Li( )Kaipeng WangXiwu GuZhiyong Xu
School of Computer Science and Technology, Huazhong University of Science and Technology, Wuhan 430074, China.
Math and Computer Science Department, Suffolk University, Boston, MA 02101, USA
Shenzhen Institute of Advanced Technology, Chinese Academy of Science, Shenzhen 518055, China.
Show Author Information

Abstract

We propose a novel hybrid method to analyze the security vulnerabilities in Android applications. Our method combines static analysis, which consists of metadata and data flow analyses with dynamic analysis, which includes dynamic executable scripts and application program interface hooks. Our hybrid method can effectively analyze nine major categories of important security vulnerabilities in Android applications. We design dynamic executable scripts that record and perform manual operations to customize the execution path of the target application. Our dynamic executable scripts can replace most manual operations, simplify the analysis process, and further verify the corresponding security vulnerabilities. We successfully statically analyze 5547 malwares in Drebin and 10 151 real-world applications. The average analysis time of each application in Drebin is 4.52 s, whereas it reaches 92.02 s for real-word applications. Our system can detect all the labeled vulnerabilities among 56 labeled applications. Further dynamic verification shows that our static analysis accuracy approximates 95% for real-world applications. Experiments show that our dynamic analysis can effectively detect the vulnerability named input unverified, which is difficult to be detected by other methods. In addition, our dynamic analysis can be extended to detect more types of vulnerabilities.

References

【1】
【1】
 
 
Tsinghua Science and Technology
Pages 589-603

{{item.num}}

Comments on this article

Go to comment

< Back to all reports

Review Status: {{reviewData.commendedNum}} Commended , {{reviewData.revisionRequiredNum}} Revision Required , {{reviewData.notCommendedNum}} Not Commended Under Peer Review

Review Comment

Close
Close
Cite this article:
Tang J, Li R, Wang K, et al. A Novel Hybrid Method to Analyze Security Vulnerabilities in Android Applications. Tsinghua Science and Technology, 2020, 25(5): 589-603. https://doi.org/10.26599/TST.2019.9010067

1674

Views

143

Downloads

33

Crossref

N/A

Web of Science

37

Scopus

2

CSCD

Received: 30 October 2019
Accepted: 04 November 2019
Published: 16 March 2020
© The author(s) 2020

The articles published in this open access journal are distributed under the terms of the Creative Commons Attribution 4.0 International License (http://creativecommons.org/licenses/by/4.0/).